Breaking
Neural Interfaces

Experts Urge Businesses to Strengthen Cybersecurity Measures

By Lorenzo Ferretti 3 min read
Experts Urge Businesses to Strengthen Cybersecurity Measures - cybersecurity measures
ASOS investigated potential exposure of customer data after an October 6 security incident.

October marks Cybersecurity Awareness Month, an annual reminder for businesses to review their security practices. This year, the focus is on actionable advice from industry experts.

Threats range from fake invoices to AI-generated messages mimicking trusted contacts.

A recent incident involving ASOS highlighted these risks. On October 6, customers saw an “ASOS HACKED” notification, prompting an investigation into potential exposure of names and contact details. While payment and password data remained secure, the breach highlighted the vulnerability of modern businesses, especially those relying on cloud platforms and external services.

Expert Advice for Businesses

Cybersecurity leaders shared their top recommendations. Here’s what they advised:

Harvey Dhillon from Zmartly warns: “Never change supplier bank details via email. Always verify changes by phone using a known number.” This prevents scams exploiting urgency.

Sarah Bone at YEO Messaging cautions against trusting logins alone: “Attackers hijack sessions after initial access. Continuous verification is key.” Ongoing identity checks are essential.

Fraudsters use stolen credentials and AI impersonation, requiring stronger, multi-signal authentication.

Hardware-backed passkeys offer superior security and compliance with regulations like PCI DSS 4.0.”

Jackson Schultz at ArgusEye advises: “Assess risk beyond technical severity. Understand how vulnerabilities connect to real-world systems.” A flaw in a water treatment system, for instance, poses greater risk than one in an isolated device.

This minimizes risks from unsupervised AI.

As businesses adopt AI, Khushboo Kashyap from Vanta warns of shadow AI: “Inventory all AI systems and set guardrails. Make approved paths easier than risky shortcuts.”

Finally, Lianne Potter at Northstar Intelligence emphasizes behavior over awareness: “Understand why risky behaviors occur and make secure options practical.” Awareness training alone isn’t enough.

Challenges for Small Teams

Smaller teams face heightened pressure due to limited resources. Young companies often adopt cloud tools, payment processors, shared credentials, freelance workers, and AI assistants early on, long before hiring staff to manage these systems. As a result, their digital risk inventory grows rapidly, while the headcount to address these risks remains small. This imbalance forces them to prioritize risks and seek scalable solutions to manage their expanding attack surface.

The Broader Context

Nic Sarginson’s push for passkeys addresses a fundamental weakness: password reliance. They help meet standards like PCI DSS 4.0 and NIS2.

Evgenii Arsentev’s approach to AI agents addresses rapid AI adoption without governance. Treating AI like a new employee—limiting access and reviewing logs—mitigates risks from unsupervised tools.

The ASOS incident reminds us cybersecurity is a continuous challenge. While their swift response limited damage, it highlights the need for proactive measures. Following expert advice helps businesses strengthen defenses and reduce breach risks.

As Cybersecurity Awareness Month continues, businesses must move beyond checklists to embed security into their culture. Whether verifying supplier changes, adopting passkeys, or managing AI risks, the goal is building resilience in a complex digital environment.

Addressing the Human Element in Cybersecurity

A key theme is the importance of addressing the human element. Lianne Potter notes awareness training is insufficient; businesses must understand risky behaviors’ causes and make secure options practical.

The Role of Continuous Verification and Passkeys

Mary Ann Miller and Sarah Bone stress continuous verification, a shift from one-time checks. As attackers exploit session hijacking and AI impersonation, multi-signal authentication and interaction monitoring are vital.

Contextual Risk Assessment and AI Governance

Jackson Schultz proposes a detailed risk assessment approach, considering vulnerability context. A critical system flaw, like in water treatment, poses greater risk than an isolated device flaw, regardless of technical severity.

Lorenzo Ferretti

Leave a Reply

Your email address will not be published. Required fields are marked *